nexapps — home

Legal

Pausa Privacy Policy

Draft — not yet in effect.

  1. 1. The short version
  2. 2. Scope and definitions
  3. 3. What data we handle, and where it lives
  4. 4. Purposes and legal bases
  5. 5. Who receives data (named processors)
  6. 6. International transfers
  7. 7. Retention and deletion
  8. 8. Your rights
  9. 9. US consumer health data (Washington MHMDA and similar laws)
  10. 10. Notifications and marketing choices
  11. 11. Consent, and how to revoke it
  12. 12. Security
  13. 13. Children
  14. 14. Changes to this policy
  15. 15. Contact

App: Pausa (iOS)
Developer / data controller: Nexapps Bilişim ve Yazılım Hizmetleri Limited Şirketi, Soğanlık Yeni Mah., Soğanlık D-100 Kuzey Yanyol Cad., A Blok No: 72/2, İç Kapı No: 10, Kartal, İstanbul, Türkiye — operated by Furkan Tanrıöver
Contact: support@nexapps.co

1. The short version

Pausa is a perimenopause wellness journal that turns your daily check-ins into a weekly pattern narrative and a report you can bring to your clinician. It is built local-first:

The rest of this policy is the long version of those five sentences.

2. Scope and definitions

This policy covers the Pausa iOS app and the nexapps platform services behind it. It does not cover Apple’s own processing (App Store purchases, iCloud Backup, iOS notifications), which Apple describes in its own privacy documentation.

3. What data we handle, and where it lives

3.1 Data stored on your iPhone (we never receive it)

Stored in Pausa’s local, on-device database (SwiftData). Pausa never writes your health data to iCloud: it uses no CloudKit sync and no iCloud Drive, as Apple’s App Review Guideline 5.1.3(ii) requires. Like the rest of your iPhone’s app data, the database is part of your iPhone’s own encrypted backup: if you have iCloud Backup turned on, that backup — which Apple runs, not us — may include it.

Notes on control:

3.2 The transient AI summary (leaves your device only with your explicit consent)

To write your weekly pattern narrative (about once a week) and your monthly report summary, the app computes a condensed statistical summary on your device and sends it to our server. This happens only after you have accepted the in-app health-data and AI consent screen, and you can turn it off at any time.

Your de-identified summary is processed by Anthropic, our AI provider.

What the summary contains: aggregated statistics and structured severity series derived from your entries for the period being analyzed — e.g. symptom frequency and severity aggregates, sleep-quality aggregates, cycle-phase markers, and adherence indicators — plus non-identifying request metadata (app identifier, feature name, app version).

What it never contains: your name, email address, phone number, contacts, precise location, advertising identifiers, device fingerprints, photos, or free text (none exists — see §3.1).

The path it takes: your device → our server in Germany (EU) → Anthropic’s API, encrypted in transit (TLS) on both legs. Our server sends Pausa’s AI requests straight to Anthropic: they never pass through Cloudflare’s AI Gateway or any other AI routing service. The provider is:

What is stored, and by whom:

Provider changes: we name our AI provider here deliberately. Adding or replacing a provider is a change to this policy — we will update it and, where the change is material, ask for your consent again before your data reaches a new provider.

3.3 Account and device data (on our servers)

Pausa works without registration. On first launch the app creates a pseudonymous account:

There is no sign-in of any kind: Pausa never asks for your name, email address or phone number.

3.4 Purchases and subscription state

Payments are processed by Apple through the App Store; we never see your payment card details. To know which features you’re entitled to, we use RevenueCat (subscription management) which processes: your pseudonymous account identifier, product identifier, subscription state (trial, active, cancelled, billing issue, expired), period dates, and store transaction identifiers. Our servers keep a mirror of that entitlement state.

3.5 Usage analytics (content-free, EU-hosted)

We measure how the product performs using PostHog (EU Cloud, hosted in the EU). Analytics never contain your health entries — this is an engineering rule, not just a policy: apps on the nexapps platform cannot send analytics directly; events flow through our server, which stamps identity server-side and forwards a fixed, content-free event taxonomy.

3.6 Diagnostics

Crash and error reports via Sentry (EU region), configured to scrub personal data. No health content, emails, tokens, or request/response bodies are included in error reports or server logs. Error reports carry no account identifier. Sentry’s own software adds a hashed device identifier to each error report and a random installation identifier to its app-stability data, so that reports from one installation can be grouped; neither is connected to your account.

3.7 Transactional email

Pausa never asks for your email address, so we send you no email — no marketing email, and no account email either: account deletion is confirmed in the app (§7). If you write to us, we use your address and your message only to answer you; our mailbox is hosted by Google (Google Workspace).

3.8 What we never collect

No precise location. No contacts. No photos. No microphone. No browsing or search history. No advertising identifiers (no ATT prompt — there is nothing to track). No third-party advertising or tracking SDKs. We do not sell or rent any data, and we do not share any data for advertising. Pausa shows no ads and embeds no third-party trackers or advertising identifiers — there is nothing to track.

PurposeData usedGDPR basisKVKK basis
Provide the journal (local features)On-device dataArt. 6(1)(b) contract (processing is on your device; largely outside our controller reach)Art. 5/2(c) performance of contract
Generate weekly narrative / monthly reportTransient AI summary (§3.2)Art. 6(1)(a) + Art. 9(2)(a) explicit consentArt. 6 açık rıza (explicit consent — health data is special-category)
Account, session, security, abuse preventionAccount data (§3.3)Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interest (security)Art. 5/2(c), 5/2(f)
Subscription entitlement and billing supportPurchase data (§3.4)Art. 6(1)(b) contractArt. 5/2(c)
Product analytics and service improvementContent-free usage events (§3.5)Art. 6(1)(f) legitimate interest (content-free, pseudonymous, server-proxied, opt-out via deletion)Art. 5/2(f) meşru menfaat
Diagnostics and reliabilityCrash data (§3.6)Art. 6(1)(f) legitimate interestArt. 5/2(f)
Lifecycle notificationsPush token, entitlement stateArt. 6(1)(b)/(f); marketing-style pushes with in-app opt-out (§10)Art. 5/2(c)/(f)
Legal complianceMinimal records as requiredArt. 6(1)(c)Art. 5/2(a),(ç)

Where the law of the country you live in requires your consent for a purpose in this table, consent is the basis we rely on for it: for health data and the AI summary, the explicit consent you give on the in-app consent screen (§11), which you can withdraw in the app at any time; for the other purposes, the consent you give by using Pausa after this policy has been made available to you, which you can withdraw by deleting your account (§7).

Health-related data is never used for advertising, marketing, data mining, or any purpose other than the health-management features you asked for (this is also an App Store rule for health apps, Guideline 5.1.3(i), and we adopt it as a binding commitment).

5. Who receives data (named processors)

We use a small number of service providers (“processors”). Each processes data for us under its own data-processing terms. We confirm, per Apple Guideline 5.1.1(i), that each provides the same or equal protection of your data as stated here.

ProviderRoleWhat it processesLocation
Anthropic, PBCAI provider (§3.2)Transient AI summary; generated narrative textStored in the USA; processed in the USA, Europe, Asia or Australia (§3.2)
Cloudflare, Inc.Encrypted backup storage (R2)Encrypted database backups (no health content — §7)Global/USA
Hetzner Online GmbHServer hostingAll server-side data (§3.3–3.5 staging)Germany (EU)
RevenueCat, Inc.Subscription managementPseudonymous account ID, subscription stateUSA
PostHog (EU Cloud)Product analyticsContent-free usage events, pseudonymous IDEU
Functional Software, Inc. (Sentry, EU region)Crash/error reportingPII-scrubbed diagnosticsEU
Google (Google Workspace)Our emailYour email address and message, only if you write to us (§3.7)USA/global
Apple Inc.App distribution, payment, push delivery (APNs)Per Apple’s own policiesUSA/global

We have no advertising partners, no data brokers, and no affiliates. We do not disclose health-related data to any third party except the processors above, for the purposes above, with your consent where required.

6. International transfers

Pausa is operated from Türkiye, our servers are in Germany, and some of the processors in §5 are in the United States. Using Pausa therefore moves data across borders: to our servers in Germany (Hetzner), to the EU-hosted analytics and crash-reporting services (PostHog, Sentry), and to processors based in the United States — Anthropic for the transient AI summary, RevenueCat for subscription state, Cloudflare for encrypted backups, and Google for any email you send us. Anthropic may also process the summary in Europe, Asia or Australia (§3.2). Each receives only the data §5 lists, for the purpose §5 states, and processes it under its own data-processing terms.

7. Retention and deletion

DataWhereRetained
Symptom logs, narratives, reportsYour iPhone (and your iPhone’s own backup, if you use one)On your iPhone, until you delete them, delete your account in-app, or delete the app; in a backup of your iPhone, until that backup is replaced or deleted (§3.1). Under your control.
Transient AI summaryIn memory during processingNot stored by nexapps. At the AI provider: deleted within 30 days, or kept for up to two years if its automated safety systems flag the request (§3.2).
AI usage metadata (no content)Our serversWhile your account exists; on account deletion the link to your account is removed and only anonymous aggregates remain.
Account record, device recordOur serversUntil you delete your account (effects below). An account without a subscription that has not been used for 60 days is closed automatically and purged 30 days later.
Session/refresh tokensOur servers (hashed)Rotating; expire after at most 60 days without use; destroyed at deletion.
Push tokenOur serversUntil notifications are disabled, the token is invalidated, or deletion.
Consent records (the fact, time and version of each consent you give, decline or withdraw — no health content)Our serversKept after you delete your account, as the record that your consent was asked for and answered, keyed only to the account’s random identifier.
Analytics eventsOur server (staging) → PostHog EUStaged copies pruned within 7 days of forwarding. In PostHog, the plan we use has a one-year retention period, after which events no longer appear in any analysis. Your analytics profile and its events are deleted at PostHog when you delete your account. One content-free record of the deletion itself — how long the app had been installed, the subscription status, recent usage counts, the furthest step reached and the last screen and action recorded, and the app version and platform; never health content — stays in PostHog under a hashed form of the account identifier rather than the identifier itself, so that we can count account deletions; it is subject to the same one-year retention period.
Subscription recordsRevenueCat / AppleUntil account deletion (deletion request forwarded to RevenueCat); Apple retains its own transaction records under Apple’s policies.
DiagnosticsSentry30 days — the retention period of the Sentry plan we use — after which reports can no longer be accessed.
Encrypted backupsCloudflare R2 (encrypted with keys that are never stored on our servers)Daily backups are deleted after 30 days and monthly backups after 12 months. Backups never contain your symptom data — health content never reaches our databases. Records of a deleted account leave our backups as the backups that hold them are deleted on that schedule.

Deleting your account (in-app)

Settings → Delete Account. This is available to every user, requires no phone call or email, and does the following:

  1. Immediately on our servers: your account is closed and its personal data deleted; devices and session tokens are destroyed; AI usage metadata is unlinked from you. What remains is the account’s random identifier with a few content-free status fields, purged 30 days later — later only if a processor has not yet confirmed its deletion (step 3) — and your consent records (table above), which we keep.
  2. On your device: the app wipes its local database — your symptom history, narratives, and reports are erased (export first if you want to keep them). A backup of your iPhone made before the deletion keeps its copy until that backup is replaced or deleted (§3.1).
  3. At our processors (completed within 30 days): deletion of your analytics person profile at PostHog and your subscriber record at RevenueCat.
  4. Confirmation: shown in the app.
  5. Backups: deleted records persist only inside encrypted backups until those expire per the schedule above; backups are used solely for disaster recovery and are not used to “restore” deleted accounts.
Important: deleting your account does not cancel an active App Store subscription — Apple controls billing. Cancel in iOS Settings → Apple Account → Subscriptions, ideally before deleting your account. The app reminds you of this in the deletion flow.

You can also revoke AI consent without deleting anything — see §11.

8. Your rights

Depending on where you live, you have the rights below. Exercise any of them in-app (deletion, consent revocation, export) or by contacting support@nexapps.co. We do not discriminate against you for exercising rights.

Most of your data is on your device, where “access” and “portability” are direct: the encrypted local export gives you a complete copy of your health data without asking us.

9. US consumer health data (Washington MHMDA and similar laws)

The section below is our Consumer Health Data notice. It is also published as a standalone Consumer Health Data Notice, which is the authoritative version and the target of every Consumer Health Data link on the site.

This is Pausa’s Consumer Health Data Privacy Policy for the Washington My Health My Data Act (RCW 19.373), the Nevada consumer health data law (SB 370), the Connecticut Data Privacy Act’s consumer-health provisions, and similar U.S. state laws.

Categories of consumer health data we collect, and why:

CategoryCollected?Purpose
Individual health conditions, symptoms, and related logs (symptoms, severity, sleep, cycle/spotting, HRT/supplement adherence)Collected on your device only; never stored on our serversTo provide the journal, trends, narratives, and reports you request
Derived/aggregated health statistics (the transient AI summary)Processed transiently with your consent; not stored by usTo generate your narrative/report
Inferences that could reveal health status from non-health records (e.g. that your account uses a perimenopause app)Our pseudonymous account/usage records inherently indicate use of a perimenopause-support appService operation only; protected under this policy as consumer health data
Biometric, genetic, precise-location, or reproductive-health services location dataNot collected—

Sources: you (your in-app entries) and your device. Sharing: consumer health data is disclosed only to the processors named in Pausa’s Privacy Policy (the AI provider, under the transient-summary disclosure and only with your consent; infrastructure providers), each acting under its own data-processing terms. We have no affiliates. We do not sell consumer health data and do not share it for advertising. We do not use geofencing, and specifically do not geofence around any facility providing in-person health care.

Consent: we collect and process consumer health data only with your consent, obtained through a separate, plain-language in-app consent screen (not bundled into general terms acceptance) before Pausa sends any health data off your device. Collection limited to your device happens as part of the service you signed up for; nothing is transmitted without the separate consent.

Your rights (WA/NV/CT residents): the right to confirm whether we collect or share consumer health data; to access it, including a list of the third parties (and any affiliates) it was shared with; to withdraw consent; and to have it deleted — including propagation of the deletion to our processors and, on the timeline in Pausa’s Privacy Policy, to backups. Submit requests in-app or to support@nexapps.co. We respond within 45 days (extendable once by 45 days where reasonably necessary). If we refuse a request, you may appeal by replying to our decision or writing to us with the subject “Health data appeal”; we decide appeals within 45 days and, if the appeal is denied, we provide a way to contact the Washington Attorney General (or your state’s equivalent) to raise a concern.

Legal process (our subpoena policy): we do not disclose consumer health data to government entities or litigants except upon valid, binding legal process, which we review and construe narrowly; where lawful, we notify you before disclosure. Structurally, the most protective answer is architectural: we cannot produce symptom histories we do not possess — your logs are on your device, not on our servers, and we do not store the transient AI summaries. What could be produced from our systems is limited to the pseudonymous account, subscription, and content-free usage records described in Pausa’s Privacy Policy.

10. Notifications and marketing choices

Before Pausa’s first AI call, you see a consent screen describing exactly what §3.2 describes: what is sent, to whom (Anthropic), and that nothing is stored on our servers. We record the fact, time, and version of your consent (a content-free record) as required by Apple Guideline 5.1.2(i) and applicable law.

12. Security

TLS encryption for everything in transit; local data protected by iOS data protection; session tokens stored in the device Keychain; server-side refresh tokens stored only as hashes; backups encrypted with keys that are never stored on our servers; EU hosting; strict server hardening; no health content in logs; provider API keys never present in the app. No system is perfectly secure; if a breach affects you, we will notify you and regulators as required by law (including the FTC Health Breach Notification Rule where applicable).

13. Children

Pausa is a perimenopause app for adults. It is not directed to children, and we do not knowingly collect data from anyone under 16. If you believe a child under 16 has used Pausa, contact us and we will delete the associated data.

14. Changes to this policy

We will post changes here with a new effective date, and for material changes (for example, a new AI provider or any new category of data leaving your device) we will notify you in-app and, where required, ask for fresh consent. Prior versions available on request.

15. Contact

Nexapps Bilişim ve Yazılım Hizmetleri Limited Şirketi — data controller
Soğanlık Yeni Mah., Soğanlık D-100 Kuzey Yanyol Cad., A Blok No: 72/2, İç Kapı No: 10, Kartal, İstanbul, Türkiye
Email: support@nexapps.co

Applications under Türkiye’s KVKK go to the same address and are answered within 30 days — see §8.